嵌入式设备中点虚拟化技术实现文件保护的应用
2021-06-28赵晓华赵天耳刘京京
赵晓华 赵天耳 刘京京

摘 要:嵌入式设备应用广泛,具有存储容量低、实时性要求高等特点。考虑在满足嵌入式设备速度、尺寸和功耗等方面要求的同时,保证重要文件内容不被泄露是值得探究的问题。针对该问题提出一种点虚拟化技术实现文件保护的方法,实现重要文件的保护,防止非法用户静态分析、防动态调试、防进程的内存拷贝,提高设备安全性,对系统性能影响不高。
关键词:嵌入式设备;点虚拟化技术;文件保护;内存拷贝
中图分类号:TP309 文献标识码:A 文章编号:2096-4706(2021)01-0146-03
Application of Point Virtualization Technology in Embedded Device to
Realize File Protection
ZHAO Xiaohua1,ZHAO Tianer2,LIU Jingjing3
(1.Henan University Minsheng College,Kaifeng 475001,China;2.Hangzhou Shuanxiang Software Co.,Ltd.,Hangzhou 311100,China;3.Kaifeng Vocational College of Culture and Arts,Kaifeng 475001,China)
Abstract:Embedded devices are widely used,with low storage capacity and high real-time requirements. While meeting the requirements of speed,size and power consumption of embedded devices,it is worth exploring to ensure that the contents of important files are not leaked. To solve the problem,proposes a method of file protection based on point virtualization technology,which can protect important files,prevent illegal users from static analysis,dynamic debugging,memory copy of process,and improve device security,and the impact on system performance is not high.
Keywords:embedded device;point virtualization technology;file protection;memory copy
0 引 言
嵌入式Linux系統近几年来已成为研究热点,目前正在开发的嵌入式系统中有近50%的系统选用Linux作为嵌入式操作系统。目前在Linux平台上并没有很好的工具保证数据的安全性。笔者参与系统内核安全研究,研究嵌入式系统中如何在不影响系统性能的情况下实现文件保护。目前常用的方法为加密,重要文件在发布前进行加密,运行时进行解密,运行结束后删除文件。但在程序加载时磁盘上为明文数据,容易被入侵者捕获。本文提出一种基于点虚拟化技术实现的安全保护策略,自定义实现Linux系统的内核模块机制,可以实现防止非法用户静态分析、防动态调试、防进程的内存拷贝,多方面保护文件的安全性。
嵌入式Linux是将Linux系统进行修改,使之能在嵌入式计算机系统上运行的一种操作系统[1]。嵌入式Linux内核开源,可支持X86、PowerPC、ARM、XSCALE、MIPS、SH、68K、Alpha、SPARC等多种体系结构,并且可以移植到多种硬件平台上,在嵌入式设备中,占用资源更少、运行更稳定、速度更快[2]。……
